From the 1 of 1 linked paper with an AI index.
1 paper
Rasmus Torp, Shailen K. Smith, Adam Breuer
The paper shows that training data privacy against model inversion attacks is not due to memorization but to the presence of non‑robust adversarial features, and introduces a train…